Play ransomware group hits Dutch maritime firm Royal Dirkzwager

Organization
Royal Dirkzwager
Exploit
Ransomware
Industry
Maritime Logistics

Royal Dirkzwager, a Dutch maritime logistics company founded in 1872 that tracks ship movements and supplies information to hundreds of shipping and port organisations, confirmed in March 2023 that it had been hit by ransomware.

The Play ransomware group claimed the attack and added the company to its dark web leak site, publishing a sample archive of roughly 5 gigabytes as proof. The group said the stolen material included private and personal data, contracts, employee identity documents and passports, and threatened to release the remainder if its demands were not met. SecurityWeek reported that the intrusion took place on 6 March and that the leak site listing appeared on 16 March. The Record dated the listing to Monday 13 March, citing the researcher Dominic Alvieri.

Chief executive Joan Blaas said the attack did not have an effect on operations. The company did take systems offline and suspend several services, including its real time ship arrival system and its ROAM vessel traffic monitoring service, and needed roughly a week to clean and restore them. He described a heavy impact on staff, and told The Record he was in negotiations with the attackers.

Royal Dirkzwager reported the incident to the Dutch Data Protection Authority. By the middle of March the company said almost all of its services were functioning again, with remaining issues still being worked through.

Sources